MaaS360 Ask Me Anything: Microsoft Entra ID Integration
Thank you to everyone who joined our latest IBM MaaS360 Ask Me Anything (AMA) session on Microsoft Entra ID Integration.
During this session, we explored how organizations can integrate Microsoft Entra ID with MaaS360 to simplify identity management, automate user provisioning, strengthen security, and enable Conditional Access for managed devices.
Whether you're planning a new deployment or looking to enhance an existing environment, this session covered the core capabilities, deployment best practices, and common troubleshooting scenarios.
You can find the July 22nd, 2026 replay and presentation here: MaaS360 Ask Me Anything about Microsoft Entra ID Integration.
Key Takeaways:
Below is an overview of the presentation and discussion regarding Microsoft Entra ID Integration from the session.
1. Why integrate Microsoft Entra ID with MaaS360?
Managing users across multiple platforms can lead to manual administration, stale user accounts, delayed onboarding and offboarding, and increased security risk.
Integrating Microsoft Entra ID with MaaS360 helps organizations:
- Automate user lifecycle management
- Establish a single source of identity
- Centralize user authentication
- Automatically manage users through group membership
- Enable Microsoft Conditional Access
2. What is Microsoft Entra ID Integration?
The Microsoft Entra ID integration with MaaS360 brings together three key capabilities:
User Authentication
- Authenticate with Microsoft credentials
- Single identity source
- Multi-Factor Authentication (MFA) support
- Simplified device enrollment
Directory Sync
- Synchronize users
- Synchronize Groups
- Synchronize group memberships
- Automated user provisioning
Conditional Access
- Verify device compliance
- Validate device trust
- Control access to corporate resources
- Enforce security policies based on identity and compliance
Microsoft Entra ID serves as the organization's identity provider, while MaaS360 manages endpoint security and compliance.
3. Automate common identity management tasks
The integration helps streamline several everyday administrative processes, including:
Employee Updates:
- Department changes
- Group membership changes
- Access changes
- Automatic synchronization
Employee Offboarding:
- Disable user accounts
- Remove access automatically
- Reduce security risks associated with inactive accounts
Conditional Access:
- Verify user identity
- Confirm device compliance
- Grant access only to trusted users and managed devices
4. Strengthen security with modern authentication
Organizations can leverage Microsoft Entra ID during device enrollment, allowing users to authenticate with their existing Microsoft credentials and Multi-Factor Authentication (MFA).
This provides:
- Enhanced security
- A modern enrollment experience
- Stronger identity verification
- Improved compliance posture
- Alignment with Zero Trust principles
- Reduced reliance on passwords alone
5. Troubleshooting Tips
When troubleshooting Microsoft Entra ID integration, we recommend following these steps before opening a support case:
- Verify the affected users or groups are assigned to the Enterprise Application.
- Review attribute mapping, especially the externalId configuration.
- Test synchronization using Provision on Demand.
- Confirm the SCIM secret token has not expired.
- Allow sufficient time for scheduled synchronization to complete.
- Review Microsoft Entra provisioning logs and MaaS360 notifications for any reported errors.
Following this process resolves many common deployment issues without additional troubleshooting.
Frequently Asked Questions
Q: How do I migrate from on-premises Active Directory to Microsoft Entra ID while continuing to enroll devices in MaaS360?
A: When migrating from an on-premises Active Directory integration to Microsoft Entra ID, it's important to avoid having both identity sources managing the same users.
As users are migrated to Microsoft Entra ID:
- Disable the existing Cloud Extender synchronization for those users.
- Synchronize the migrated users through Microsoft Entra ID using SCIM provisioning.
- If you're syncing all users from Cloud Extender today, consider switching to LDAP synchronization so you can control which users remain on-premises while others are managed through Entra ID.
This phased approach helps prevent user authentication settings from continually switching between Active Directory and Microsoft Entra ID.
Q: Can I run both Active Directory synchronization and Microsoft Entra ID synchronization at the same time?
A: Yes. Hybrid environments are supported.
Organizations can continue synchronizing on-premises users through Cloud Extender while synchronizing cloud users through Microsoft Entra ID.
The important consideration is to avoid synchronizing the same user from both identity sources. As users are migrated to Entra ID, they should be removed from the Cloud Extender synchronization scope to prevent conflicting updates.
Q: We primarily use MaaS360 to manage our iOS devices. What are the benefits of integrating Microsoft Entra ID?
A: Microsoft Entra ID integration allows you to continue using MaaS360 as your Mobile Device Management (MDM) solution while taking advantage of Microsoft identity and security capabilities.
Benefits include:
- Microsoft Entra ID authentication during enrollment
- Automated user provisioning through SCIM
- Multi-Factor Authentication (MFA)
- Device registration for Microsoft Conditional Access
- Improved identity lifecycle management
MaaS360 continues managing devices, policies, and compliance, while Microsoft Entra ID evaluates identity and Conditional Access policies.
Q: Can I keep some users on Active Directory while migrating others to Microsoft Entra ID?
A: Yes, organizations can migrate users in phases by assigning only selected users or groups to the Microsoft Entra ID SCIM application.
This allows cloud users to be synchronized through Entra ID while remaining users continue using the existing on-premises Active Directory integration until they are ready to migrate.
Q: Some user attributes, such as Employee ID, Department, or Location, aren't synchronizing. Where should I start troubleshooting?
A: The first place to review is the attribute mapping within the Microsoft Entra Enterprise Application.
Verify that:
- The required attributes are mapped correctly.
- The mappings match the IBM MaaS360 documentation.
- Any custom attributes required by your organization are included.
If the configuration appears correct but attributes are still missing, we recommend opening a support case so IBM Support can review your specific environment and synchronization configuration.
Additional Resources
For more information, refer to the following documentation:
Thank you for being part of our IBM MaaS360 community! We hope this Ask Me Anything session provided valuable insights into Microsoft Entra ID integration and helps simplify your deployment and identity management strategy.
If you have additional questions or suggestions for future Ask Me Anything topics, we'd love to hear from you. Leave a comment below or email the IBM MaaS360 Customer Success team at csmaas@us.ibm.com.
We're already working on our next MaaS360 Ask Me Anything session, so stay tuned to the IBM MaaS360 Community for upcoming topics, webinars, and technical resources.
We look forward to seeing you at our next event!